Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Water Galura

Also known as: GOLD FEATHER

Description

Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.(Citation: BushidoToken Qilin RaaS JUN 2024)(Citation: Sophos Qilin MSP APR 2025)

AI Analysis

· 1 week ago

Executive Summary

Water Galura, also known as GOLD FEATHER, operates a Double extortion Ransomware-as-a-Service (RaaS) model since at least 2024. Primarily targeting sectors including healthcare and financial services across various countries, they demand ransom payments for decryption keys and additional fees to prevent data publication. Their operations leverage T1657 (Financial Theft), T1585.001 (Social Media Accounts), and T1486 (Data Encrypted for Impact) techniques.

Goals & Targeting

Water Galura targets industries with sensitive data, such as healthcare and finance, where the financial stakes are highest. Their geographic reach suggests a global approach, aiming for maximum disruption and payoff. Small businesses and medium-sized enterprises are particularly vulnerable, offering attractive yet defensible assets to extract high-value ransoms.

Enhanced Description

Water Galura are sophisticated cybercriminal operators of the Qilin RaaS platform, managing payload generation, ransom negotiations, and data leak sites. Since mid-2022, they've recruited affiliates on Russian forums, using double extortion to maximize revenue. Their operations typically involve encrypting victims' data, demanding ransoms for decryption keys, and additional fees to avoid public leaks of stolen information. Water Galura's strategic focus on high-value sectors ensures maximum impact on their targets.

Key Capabilities

  • Double extortion tactics via Qilin RaaS
  • Recruitment of attack affiliates through cybercrime forums
  • Use of social media manipulation for influence
  • Advanced financial theft strategies

MITRE ATT&CK Tactics

Collection
Exfiltration
Disruption
Influence Operations

ATT&CK Techniques

T1657
T1585.001
T1486

Software / Tooling

Qilin Ransomware

Campaigns & Victims

Water Galura's campaigns often involve structured attacks on SMEs and critical sectors, using forums to recruit affiliates. Their operations include targeting countries in Eastern Europe and North America, leveraging double extortion for maximum impact, as seen in a late 2024 incident affecting healthcare providers.

IOC Patterns

  • Spear-phishing with malicious links leading to Qilin payloads
  • Encrypted communication channels for data exfiltration
  • Modified RDP protocols for initial access

Recommended Actions

  • Implement multi-factor authentication (MFA) for RDP access points
  • Conduct regular audits of sensitive business file directories
  • Monitor dark web marketplaces for exposed credentials or data dumps
  • Run phishing simulations to test user susceptibility
  • Ensure offline backups stored securely with immutable storage

Suggested Tags

APT
Ransomware
Financial
Cybercrime

Confidence Assessment

Moderate; information from Sophos and BushidoToken is reliable, but gaps remain in their recruitment tactics and initial attack methods beyond Qilin.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Sophos Qilin MSP APR 2025 — Bradshaw, A. et al. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. Retrieved September 26, 2025.
  2. BushidoToken Qilin RaaS JUN 2024 — Thomas, W. (2024, June 12). Tracking Adversaries: The Qilin RaaS. Retrieved September 26, 2025.

Intel Summary

3

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

2

Tactics

Tags

Ransomware
Supply Chain Attack
Data Exfiltration
APT
Financial
Cybercrime

Details

MITRE ID
G1050
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--be8847e0-9512-45db-895e-f871ab6d3820
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.